Read this one

What it cannot do

Every detector has limits. Most of them hide theirs. Here are Grainprint's, in plain language, because knowing when a tool is wrong is more useful than knowing when it is right.

Never use this as proof

Grainprint reports evidence, not guilt. Do not use it to accuse a student, an employee, an artist or anyone else. A confident looking result on a screenshot is worth nothing, and the tool will tell you so if you read the notes it prints.

Missing evidence is not evidence

No camera data and no sensor pattern is the normal state of every screenshot and every image downloaded from social media. Those platforms delete metadata and re compress the picture on upload, which erases exactly the traces this tool depends on. An image that fails every test may simply have been through Instagram.

Records can be faked

Tier 1 results are strong because nothing adds them by accident, not because they are impossible to fake. Anyone can copy a Content Credentials record from one file into another, or write camera metadata by hand. Grainprint reads these records but does not check their cryptographic signatures, so treat a declaration as a very good clue rather than a certificate.

The thresholds are not perfectly calibrated

The pixel level cut off points come from measuring known test cases, not from a large labelled collection of real and generated photographs. They are set cautiously on purpose. Benford's law is included because it is interesting but it carries almost no weight in the verdict, precisely because it is uncalibrated here.

Some real photos will look fake

A photo will fail the sensor tests if it was resized, screenshotted, heavily compressed, or exported through a design tool. Modern phones correct lens flaws in software, so a good phone photo may show no lens signature at all. Strong noise reduction flattens grain. Studio lighting at low ISO produces very clean images. Each of these pushes a genuine photo toward an AI verdict, which is why every finding is printed with its innocent explanation attached.

Some fakes will look real

Every signal here can be defeated on purpose by someone who knows about it. Add grain that scales with brightness, apply a slight radial colour shift, resample carefully, strip the metadata, and most of these tests go quiet. Grainprint is built to catch the ordinary case, not a determined adversary.

Graphics are not photographs

A logo, chart, icon, screenshot or any image with a transparent background fails every sensor test by construction, because it never went near a sensor. Grainprint detects true transparency and, when it finds it, reports the sensor tests but keeps them out of the verdict. A hand drawn logo would fail them exactly as a generated one does, so letting them vote would mark every graphic as AI.

Editing is not generating

Grainprint can often tell that a file has been re saved, cropped, or built from more than one source. That is a fact about the file's history. A heavily edited photograph is still a photograph, and a generated image that was never touched again is still generated. Do not read a "re saved" note as an accusation.

It only reads still images

JPEG, PNG, WebP, AVIF, HEIC, GIF, BMP and TIFF. Not video, not audio, not text. If a browser cannot decode a format, Grainprint falls back to reading the metadata alone and says clearly that it did.

What it is genuinely good at

Reading declarations that generators leave behind, which catches a large share of everyday AI images. Recognising an unmodified camera file with high confidence. Telling you honestly when a file has been through so much processing that no answer is possible. That last one is the most underrated feature here.

The privacy part is not a limit

Grainprint makes no network requests once the page has loaded. Your image is opened by your own browser, analysed on your own device, and never sent anywhere. There is no server that could keep it, because there is no server.